Key takeaways Zero trust is an architecture and a set of principles, not a product. NIST is explicit that no single component delivers it. The central shift is away from deciding trust by network location and towards deciding it per request, per resource, against current signals. Zero trust network access replaces the network-level tunnel with […]
Read MoreKey takeaways Moving to the cloud transfers some responsibilities to your provider and none of the ones that cause most breaches. Your data, your access rights, your configuration and your monitoring stay yours at every service level. IBM puts the global average cost of a breach at US$4.99 million in 2026, a record and a […]
Read MoreKey takeaways The ransom is the smaller number. Recovery now costs an average of US$1.7 million per incident before any ransom is counted, and that figure rose 11 percent in a year even as ransom demands fell. The entry point has moved. For the first time in four years, exploited vulnerabilities are not the leading […]
Read MoreKey takeaways The research released around Black Hat USA 2026 agrees on one thing: AI has compressed attacker timelines, but the way intruders get in has not changed. Phishing was the initial access method in more than half of Cisco Talos incident response engagements last quarter, and authentication abuse appeared in 65 percent of them. […]
Read MoreAttackers have been taking administrative control of the Wi-Fi gateways that hotels and conference centres use to run their guest networks, then quietly rewriting DNS so that travelling employees who try to reach Microsoft 365 land on a page the attacker controls instead. The activity was documented by ReliaQuest Threat Research and has been running […]
Read MoreKey takeaways MFA is the single highest-value security control most businesses can deploy, and it is usually low-cost or free. Microsoft reports it blocks more than 99% of automated account-compromise attacks, the kind that make up the vast majority of what hits your business daily. Not all MFA is equal. SMS codes are the weakest […]
Read MoreKey takeaways: HackOnChat is a global scam, uncovered by security firm CTM360, that hijacks WhatsApp accounts using fake login pages. It works two ways: hijacking your WhatsApp Web session, or tricking you into handing over a verification code. The scam spreads through trust. Once an account is taken over, it messages that person’s contacts asking […]
Read MoreKey takeaways: Every October, Cybersecurity Awareness Month is a reminder to check your online habits and tighten them. You are not too small to be a target. Everyday users and small businesses are hit just as often as large ones. Four habits cover most of the risk: strong unique passwords, multi-factor authentication, phishing awareness, and […]
Read MoreKey takeaways: Your password is the first line of defence for almost everything you do online, more important than any software. The biggest risk is reuse. If one site is breached, attackers try that same password everywhere else you use it. Length beats complexity. A long passphrase made of several random, unrelated words is both […]
Read MoreKey takeaways: Cybersecurity isn’t only for IT teams. If you use email, online banking, or social media, you are already part of it. Most online harm starts with an ordinary, avoidable mistake, like a reused password or a convincing scam message. You are not too small to be a target. Most attacks are automated and […]
Read More